MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 37519eb21f118335babdd250c584fa6bfabec67bcbe05b4059449f454ea60d05. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 37519eb21f118335babdd250c584fa6bfabec67bcbe05b4059449f454ea60d05
SHA3-384 hash: 3cab456f6bf75a396be029742a91d13b8e10255bdc21b315c16715e087692aad950c94d4136c67654876fe715fdc1ad8
SHA1 hash: e8fb8985217a1d113a9ae5bba9a184835faccc0e
MD5 hash: d83a83965d141a0676ea6daaf259518e
humanhash: west-golf-sixteen-coffee
File name:smart.sh
Download: download sample
File size:1'222 bytes
First seen:2026-02-13 08:58:49 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:AkPtGqLZE0ZGekjIg3e3TzmHTn2DOIRwOthxeTluMtI17KGPyHJZ:AGtGWESrkZ3gMjCO1Oth0J+RKGPGH
TLSH T1FD2167E6D1608CF16E8D4507B9D970505A83812FCA04AD7AF4ED299C2F38CA77171F36
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
30
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=36d1dfec-1900-0000-3784-bc9daa090000 pid=2474 /usr/bin/sudo guuid=902c8eee-1900-0000-3784-bc9db0090000 pid=2480 /tmp/sample.bin guuid=36d1dfec-1900-0000-3784-bc9daa090000 pid=2474->guuid=902c8eee-1900-0000-3784-bc9db0090000 pid=2480 execve guuid=6e43e5ee-1900-0000-3784-bc9db2090000 pid=2482 /usr/bin/rm guuid=902c8eee-1900-0000-3784-bc9db0090000 pid=2480->guuid=6e43e5ee-1900-0000-3784-bc9db2090000 pid=2482 execve guuid=a7a33bef-1900-0000-3784-bc9db4090000 pid=2484 /usr/bin/wget guuid=902c8eee-1900-0000-3784-bc9db0090000 pid=2480->guuid=a7a33bef-1900-0000-3784-bc9db4090000 pid=2484 execve
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux upx
Behaviour
System Network Configuration Discovery
UPX packed file
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 37519eb21f118335babdd250c584fa6bfabec67bcbe05b4059449f454ea60d05

(this sample)

  
Delivery method
Distributed via web download

Comments